AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationEUUnacceptable riskHigh riskLimited riskMinimal risk

EU AI Act (Regulation (EU) 2024/1689)

Issued by

European Commission

liveEffective 2024-08-01EU AI ActUpdated September 2026
Official document →

The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

The EU AI Act (Regulation (EU) 2024/1689) is the European Union's main law on artificial intelligence. It entered into force on 1 August 2024. It covers providers, the organizations that build an AI system or put it on the market, and deployers, the organizations that use one in their work. It also reaches companies outside the EU when their AI is used in the EU. The Act sorts AI by risk. A short list of practices is banned outright, including social scoring, manipulation that exploits people's vulnerabilities, untargeted scraping of facial images, and emotion recognition at work or in schools. High-risk systems, such as AI used in hiring, credit scoring, education, and critical infrastructure, must meet strict requirements before use. Systems that talk to people or generate content carry transparency duties. Everything else is minimal risk and largely unregulated. General-purpose AI models, the large models behind chatbots and coding assistants, have their own rules. Providers must keep technical documentation, publish a summary of their training content, and follow EU copyright law. Models classed as posing systemic risk, the most capable ones, carry extra duties. These include safety evaluations, serious incident reporting, and cybersecurity protections. Obligations phase in over several years. The bans and the AI literacy duty have applied since 2 February 2025. The general-purpose AI rules, governance provisions, and penalties followed on 2 August 2025. Regulation (EU) 2026/1744 then moved the high-risk deadlines. Stand-alone high-risk systems now have until 2 December 2027, and AI built into regulated products has until 2 August 2028. The same amendment added two bans from 2 December 2026 and softened the AI literacy duty to one of supporting staff literacy. National market surveillance authorities enforce the Act in each member state. The European AI Office supervises general-purpose AI models. Fines reach EUR 35 million or 7% of worldwide annual turnover for banned practices, whichever is higher. Most other breaches carry fines of up to EUR 15 million or 3%.

Key Requirements

  • •Stop any banned practice listed in Article 5. The original bans have applied since 2 February 2025.
  • •Stop any AI system that generates child sexual abuse material or non-consensual intimate images, banned from 2 December 2026.
  • •Take measures that support AI literacy among staff who operate or oversee AI, matched to their role (Article 4, as amended in 2026).
  • •Classify every AI system you build or use against the Act's risk tiers, and record the reasoning.
  • •For high-risk systems, providers need risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity controls, a conformity assessment, and registration in the EU database.
  • •Deployers of high-risk systems must follow the provider's instructions, assign trained people to oversee the system, keep its logs, and inform affected workers. Public bodies and some private deployers must also assess the impact on fundamental rights.
  • •Tell people when they are dealing with an AI system, and label deepfakes and other AI-generated content (Article 50).
  • •Providers of general-purpose AI models must keep technical documentation, publish a training content summary, and adopt a copyright policy. Models with systemic risk carry extra duties.

What Your Organization Must Do

  • →Build an inventory of the AI systems you use or develop, including tools bought from vendors, and classify each one against the risk tiers.
  • →Confirm that no system falls into a banned category, including the two bans added for December 2026, and record that review with a named owner.
  • →Run a role-based AI literacy program and keep training records you can show a regulator.
  • →For each high-risk system, plan back from its deadline of 2 December 2027 or 2 August 2028. Book conformity assessment early, since the independent assessors who run it have limited capacity.
  • →Add AI Act terms to vendor contracts: technical documentation, access to logs, incident notice, and evidence of conformity.
  • →Check whether changing or rebranding a vendor's model would make you its provider, which brings the provider duties with it.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Governance Controls

Operational controls that implement requirements from this regulation.

AGT-001Agent Permission BoundariesAGT-002Agent Prompt Injection DefenseAGT-003Agent Memory and Context GovernanceAGT-004Multi-Agent Trust HierarchyAGT-005Human Approval Gate for Irreversible Agent ActionsAGT-006Agent Action Audit TrailAGT-007Agent Scope and Task BoundariesAGT-008Agent Environment IsolationAGT-009Agent and Non-Human Identity ManagementAGT-012Agent Kill Switch and Emergency StopAGT-020RAG Retrieval Boundary Controls for Regulated DataAGT-021Human Oversight Classification Rationale LogALC-001AI Decision LoggingALC-002High-Risk AI Audit TrailALC-003AI Log Retention PolicyALC-004AI Explainability DocumentationALC-005Regulatory Audit ReadinessBRD-011AI Governance Training Program and Completion TrackingCHM-001AI Model Version ControlCHM-002Model Deployment Gate ProcessCHM-003Model Rollback and Emergency ShutdownCHM-004AI Model Change DocumentationCHM-005Model Deprecation ProcedureCMP-001Multi-Jurisdiction AI Regulatory Compliance MappingCMP-005Regulatory Engagement Process for AI Standards DevelopmentCMP-006AI Content Watermarking and Labeling ComplianceCMP-007EU AI Act Conformity Assessment and FRIA ProcessDGC-001Training Data ProvenanceDGC-002PII Handling in AI SystemsDGC-003Data Minimization for AI SystemsDGC-004AI Output Retention and DeletionDGC-005Cross-Border Data Transfer Controls for AIHOC-001AI System Risk ClassificationHOC-002Human Approval Gate for Consequential AI DecisionsHOC-003AI Output Review WorkflowHOC-004Automation Bias PreventionHOC-005Reviewer Competency RequirementsHOC-006Override and Escalation ProceduresHOC-007Board AI Risk Reporting and Escalation ThresholdsIRC-001AI Incident ClassificationIRC-002AI Incident Response PlaybookIRC-003AI Harm Notification ProceduresIRC-004AI Post-Incident ReviewIRC-005AI Incident Log and TrackingIRC-006Cross-Jurisdictional Incident Reporting TrackerMGV-001AI Model Preview and Staged Release PolicyMGV-002AI System Intake and Approval WorkflowMGV-005Generative AI Input Data ClassificationMGV-007Emerging AI Modality Classification and Governance ExtensionMGV-008AI-Generated Deliverable Disclosure and Citation StandardsMGV-009AI Capability Claim Substantiation StandardMGV-010AI Output Pre-Publication Verification for High-Stakes ClaimsMON-001AI Performance BaselineMON-002Model Drift DetectionMON-003AI Bias and Fairness MonitoringMON-004AI Output Anomaly DetectionMON-005Continuous Model EvaluationPRC-001AI Vendor Due DiligencePRC-002AI Contractual RequirementsPRC-003Third-Party AI Model EvaluationPRC-004Vendor AI Incident Notification RequirementsPRC-005AI Procurement Risk AssessmentPRC-008Vendor Model Update Disclosure and Re-Assessment ProtocolPRC-010AI Vendor Financial Stability AssessmentPRC-014Shadow AI and Third-Party Widget Inventory and ClassificationPRC-015Procurement-Stage AI Governance ConditionsPRC-017AI Evaluator and Auditor Independence AssessmentSAF-001Hallucination Detection and MitigationSAF-002AI Output ValidationSAF-003AI Graceful DegradationSAF-004AI Reliability TestingSAF-005Harmful Content FilteringSCT-001Anthropomorphic and Companion AI SafeguardsSCT-007Consumer and External AI Tool Acceptable Use PolicySCT-008AI-Specific External Complaints and Redress MechanismSCT-009AI System Algorithm RegisterSEC-001Prompt Injection PreventionSEC-002AI System Access ControlsSEC-003Sensitive Data Handling in AI PipelinesSEC-005Adversarial Robustness Testing

Frequently Asked Questions

When does the EU AI Act apply?
The Act applies in stages, starting from its entry into force on 1 August 2024. The bans and the AI literacy duty have applied since 2 February 2025. General-purpose AI rules, governance provisions, and penalties have applied since 2 August 2025. Two added bans apply from 2 December 2026. After Regulation (EU) 2026/1744, stand-alone high-risk systems must comply by 2 December 2027, and AI built into regulated products by 2 August 2028.
Does the EU AI Act apply to companies outside the EU?
Yes, it applies when a company places an AI system on the EU market or when the system's output is used in the EU. Providers based outside the EU that offer high-risk systems or general-purpose AI models must appoint an authorised representative in the EU.
What counts as a high-risk AI system?
AI can be high-risk in two ways. The first is AI that works as a safety component of a product already covered by EU product law, such as a medical device or machinery (Annex I). The second is AI used in the eight areas listed in Annex III. Those areas are biometrics, critical infrastructure, education, employment, and access to essential services such as credit and insurance. They also include law enforcement, migration and border control, and justice and democratic processes.
Which AI practices are banned?
Article 5 bans manipulative techniques that cause significant harm, exploiting people's age, disability, or economic situation, and social scoring. It also bans predicting crime from personality traits alone, untargeted scraping of facial images, and emotion recognition at work or in schools. Biometric categorisation that infers sensitive traits is banned, and real-time remote biometric identification in public spaces for law enforcement is allowed only in narrow cases. From 2 December 2026, AI that generates child sexual abuse material or non-consensual intimate images of real people is banned too.
What are the fines under the EU AI Act?
Using a banned practice can cost up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches carry up to EUR 15 million or 3%. Giving regulators incorrect or misleading information carries up to EUR 7.5 million or 1%. Smaller companies pay the lower of the two amounts.
Does the Act apply if we only use AI tools from vendors?
Yes, because deployers have their own duties, including AI literacy, transparency to the people affected, and oversight of high-risk systems. A banned practice stays banned no matter who built the tool. Heavily modifying a vendor's system or selling it under your own name can also make you its provider.